New-hire provisioning
Who creates the account, assigns the starting role set and licence, and confirms it matches the job-not a template copied from the last hire.
Independent IT security review
Most privileged-role and licensing findings trace back to how an identity was created, changed, or removed. This review reads the joiner-mover-leaver procedure itself, and checks whether it was actually followed.
Most privileged-role and licensing findings trace back to how an identity was created, changed jobs, or left-not to any single setting. This review reads the actual joiner, mover, and leaver procedure alongside evidence of whether it was followed.
Who creates the account, assigns the starting role set and licence, and confirms it matches the job-not a template copied from the last hire.
Whether access and licence assignments are updated when someone changes role, location, or manager, or simply accumulate alongside the old ones.
Who is notified when employment ends, what is disabled immediately versus later, and how contractors and fixed-term staff are handled.
A missed step in this process rarely shows up as its own finding. It reappears later as a privileged-role assignment nobody can explain or a licence nobody can account for.
Connect an administrative or elevated assignment back to the hire, promotion, or project that originally justified it.
Identify accounts that still hold paid licences and mailbox access weeks or months after the person’s last day.
Find distribution lists, Teams, and SharePoint sites still owned by someone who has moved on or left.
A joiner-mover-leaver process only works if it fits how HR, managers, and IT actually communicate-not an idealized flow with no connection to what triggers a ticket.
Confirm what event starts the process-an HR system change, a manager email, a signed form-and how reliably it reaches IT.
Clarify who confirms the access a mover needs and who confirms a leaver’s last day, since IT rarely owns either fact alone.
Extend the same discipline to contractors, temporary staff, and personnel from a partner organization who hold accounts but sit outside the regular HR record.
Disabling today’s stale accounts helps once. A dated process failure needs an owner and a way to notice the next one.
Separate the one-time account cleanup from the procedural change needed so the same gap does not reappear in six months.
Define a realistic cadence and owner for comparing active accounts against current staff, sized to the organization rather than a generic quarterly rule.
Keep the updated procedure, its owner, and the date it last worked attached to the record, not only the fixed accounts.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.